CVE-2024-37310

EVerest is an EV charging software stack. An integer overflow in the "v2g_incoming_v2gtp" function in the v2g_server.cpp implementation can allow a remote attacker to overflow the process' heap. This vulnerability is fixed in 2024.3.1 and 2024.6.0.
Configurations

No configuration.

History

16 Dec 2024, 01:15

Type Values Removed Values Added
References
  • () https://plaxidityx.com/blog/automotive-cyber-security/ev-cyber-security-plaxidityx-discovers-critical-vulnerability-in-everest-open-source-ev-charging-firmware-stack-cve-2024-37310/ -

Information

Published : 2024-07-10 20:15

Updated : 2024-12-16 01:15


NVD link : CVE-2024-37310

Mitre link : CVE-2024-37310

CVE.ORG link : CVE-2024-37310


JSON object : View

Products Affected

No product.

CWE
CWE-122

Heap-based Buffer Overflow

CWE-190

Integer Overflow or Wraparound